This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

syswow64 virus [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I seem to have a syswow64 virus. What seem to happen is AVG blocks it, and seems to remove it but it keeps coming back. Also never see to be exactly the same name. I have tried just about everything. I have a dds log to post. I hope this is a good start. I don't seem to have a virus problem since it gets blocked, but I want it to be removed for good. Thanks in advance for any help. . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16443 BrowserJavaVersion: 1.6.0_31 Run by [removed] at 1:42:16 on 2012-06-26 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.6132.3817 [GMT -4:00] . AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Windows\system32\taskeng.exe C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe C:\Windows\system32\WUDFHost.exe C:\Windows\System32\hkcmd.exe C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\AVG\AVG2012\avgtray.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files (x86)\Linksys\Linksys Wireless Manager\LinksysWirelessManager64.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\System32\mobsync.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\AVG\AVG2012\avgcfgex.exe C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe C:\Program Files (x86)\AVG\AVG2012\avgemca.exe C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe C:\Program Files (x86)\AVG\AVG2012\avgrsa.exe C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe C:\Users\Owner\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Owner\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Owner\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Owner\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Owner\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Owner\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\SysWOW64\rundll32.exe C:\Users\Owner\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\SysWOW64\svchost.exe -k netsvcs C:\Windows\system32\taskeng.exe C:\Program Files (x86)\uTorrent\uTorrent.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uSearch Bar = Preserve uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: AVG Do Not Track: {31332eef-cb9f-458f-afeb-d30e9a66b6ba} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [nmctxth] "C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe" mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" mRun: [TrayServer] "C:\Program Files (x86)\MAGIX\Movie_Edit_Pro_15_Plus_Download_version\TrayServer.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab TCP: DhcpNameServer = 75.75.75.75 75.75.76.76 TCP: Interfaces\{8C91F51D-07B0-4519-8383-6C6ED5367944} : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{D554E48C-57A3-4F02-BF4C-44149732DBB9} : DhcpNameServer = 75.75.75.75 75.75.76.76 Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\puresp4.dll BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll BHO-X64: AVG Do Not Track - No File BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun-x64: [nmctxth] "C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe" mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun-x64: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" mRun-x64: [TrayServer] "C:\Program Files (x86)\MAGIX\Movie_Edit_Pro_15_Plus_Download_version\TrayServer.exe" mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\epodx6qi.default\ . ============= SERVICES / DRIVERS =============== . R0 AVGIDSHA;AVGIDSHA;C:\Windows\system32\DRIVERS\avgidsha.sys –> C:\Windows\system32\DRIVERS\avgidsha.sys [?] R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys –> C:\Windows\system32\DRIVERS\avgrkx64.sys [?] R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys –> C:\Windows\system32\DRIVERS\avgldx64.sys [?] R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys –> C:\Windows\system32\DRIVERS\avgmfx64.sys [?] R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys –> C:\Windows\system32\DRIVERS\avgtdia.sys [?] R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-4-4 63928] R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2012-4-11 88576] R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe [2012-4-30 5106744] R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-2-14 193288] R2 Fabs;FABS - Helping agent for MAGIX media database;C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-8-27 1253376] R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2012-4-11 1153368] R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\avgidsdrivera.sys –> C:\Windows\system32\DRIVERS\avgidsdrivera.sys [?] R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\avgidsfiltera.sys –> C:\Windows\system32\DRIVERS\avgidsfiltera.sys [?] R3 VST64_DPV;VST64_DPV;C:\Windows\system32\DRIVERS\VSTDPV6.SYS –> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?] R3 VST64HWBS2;VST64HWBS2;C:\Windows\system32\DRIVERS\VSTBS26.SYS –> C:\Windows\system32\DRIVERS\VSTBS26.SYS [?] R3 WUSB54GCv3;Compact Wireless-G USB Network Adapter;C:\Windows\system32\DRIVERS\WUSB54GCv3.sys –> C:\Windows\system32\DRIVERS\WUSB54GCv3.sys [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 WRSVC;WRSVC;"C:\Program Files (x86)\Webroot\WRSA.exe" -service –> C:\Program Files (x86)\Webroot\WRSA.exe [?] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-11 253600] S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys –> C:\Windows\system32\Drivers\usbaapl64.sys [?] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768] S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-4-11 89920] . =============== File Associations =============== . JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %* . =============== Created Last 30 ================ . 2012-06-26 05:29:07 ——– d-s—w- C:\ComboFix 2012-06-26 04:39:08 ——– d—–w- C:\sh4ldr 2012-06-26 04:39:08 ——– d—–w- C:\Program Files\Enigma Software Group 2012-06-26 04:38:28 ——– d—–w- C:\Windows\18F97AF04F884494AFE25A5702E142CC.TMP 2012-06-26 04:38:21 ——– d—–w- C:\Program Files (x86)\Common Files\Wise Installation Wizard 2012-06-26 04:29:20 ——– d-sh–w- C:\$RECYCLE.BIN 2012-06-26 04:27:25 ——– d—–w- C:\Users\Owner\AppData\Roaming\DriverCure 2012-06-26 04:27:24 ——– d—–w- C:\Users\Owner\AppData\Roaming\SpeedyPC Software 2012-06-26 04:26:56 ——– d—–w- C:\ProgramData\SpeedyPC Software 2012-06-26 04:26:56 ——– d—–w- C:\Program Files (x86)\SpeedyPC Software 2012-06-26 04:26:56 ——– d—–w- C:\Program Files (x86)\Common Files\SpeedyPC Software 2012-06-26 01:16:13 ——– d—–w- C:\Program Files (x86)\ESET 2012-06-26 00:54:08 ——– d—–w- C:\Users\Owner\AppData\Local\temp 2012-06-21 05:11:07 98816 —-a-w- C:\Windows\sed.exe 2012-06-21 05:11:07 518144 —-a-w- C:\Windows\SWREG.exe 2012-06-21 05:11:07 256000 —-a-w- C:\Windows\PEV.exe 2012-06-21 05:11:07 208896 —-a-w- C:\Windows\MBR.exe 2012-06-15 15:21:24 8955792 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A42FB8D3-25F6-46E3-A4E8-6007F953CBA6}\mpengine.dll 2012-06-15 15:18:25 209920 —-a-w- C:\Windows\System32\drivers\rdpwd.sys 2012-06-15 15:18:24 2767360 —-a-w- C:\Windows\System32\win32k.sys 2012-06-15 06:26:40 ——– d—–w- C:\Users\Owner\AppData\Roaming\SUPERAntiSpyware.com 2012-06-15 06:26:04 ——– d—–w- C:\ProgramData\SUPERAntiSpyware.com 2012-06-15 06:26:04 ——– d—–w- C:\Program Files\SUPERAntiSpyware 2012-06-15 05:30:47 ——– d—–w- C:\TDSSKiller_Quarantine 2012-06-05 02:01:03 955848 —-a-w- C:\Windows\System32\npDeployJava1.dll 2012-06-05 02:01:03 839112 —-a-w- C:\Windows\System32\deployJava1.dll 2012-05-28 07:21:39 1800704 —-a-w- C:\Windows\SysWow64\mprdin.dll . ==================== Find3M ==================== . 2012-06-02 22:15:31 2622464 —-a-w- C:\Windows\System32\wucltux.dll 2012-06-02 22:15:08 99840 —-a-w- C:\Windows\System32\wudriver.dll 2012-06-02 22:12:13 88576 —-a-w- C:\Windows\SysWow64\wudriver.dll 2012-06-02 19:19:42 186752 —-a-w- C:\Windows\System32\wuwebv.dll 2012-06-02 19:19:42 171904 —-a-w- C:\Windows\SysWow64\wuwebv.dll 2012-06-02 19:15:12 36864 —-a-w- C:\Windows\System32\wuapp.exe 2012-06-02 19:12:20 33792 —-a-w- C:\Windows\SysWow64\wuapp.exe 2012-05-18 02:06:48 2311680 —-a-w- C:\Windows\System32\jscript9.dll 2012-05-18 01:59:14 1392128 —-a-w- C:\Windows\System32\wininet.dll 2012-05-18 01:58:39 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl 2012-05-18 01:55:22 173056 —-a-w- C:\Windows\System32\ieUnatt.exe 2012-05-18 01:51:30 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2012-05-17 22:45:37 1800192 —-a-w- C:\Windows\SysWow64\jscript9.dll 2012-05-17 22:35:47 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll 2012-05-17 22:35:39 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl 2012-05-17 22:29:45 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe 2012-05-17 22:24:45 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2012-04-19 08:50:26 28480 —-a-w- C:\Windows\System32\drivers\avgidsha.sys 2012-04-13 17:46:00 1790464 —-a-w- C:\Windows\SysWow64\ipnathlp.dll 2012-04-11 21:21:22 525792 —-a-w- C:\Windows\DIFxAPI.dll 2012-04-11 20:21:02 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2012-04-11 20:20:42 70304 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-04-11 20:20:42 418464 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-04-04 19:56:40 24904 —-a-w- C:\Windows\System32\drivers\mbam.sys 2012-04-03 08:22:15 4699520 —-a-w- C:\Windows\System32\ntoskrnl.exe 2012-03-30 12:45:03 1423744 —-a-w- C:\Windows\System32\drivers\tcpip.sys . ============= FINISH: 1:42:52.10 ===============
Another log will post more aswMBR logs when done. aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-06-26 01:57:55 —————————– 01:57:55.677 OS Version: Windows x64 6.0.6002 Service Pack 2 01:57:55.677 Number of processors: 2 586 0x170A 01:57:55.678 ComputerName: OWNER-PC UserName: Owner 01:58:03.642 Initialize success 01:59:06.597 AVAST engine defs: 12062501 01:59:11.820 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 01:59:11.822 Disk 0 Vendor: ST1000DM003-9YN162 CC4D Size: 953869MB BusType: 3 01:59:11.915 Disk 0 MBR read successfully 01:59:11.918 Disk 0 MBR scan 01:59:11.922 Disk 0 Windows VISTA default MBR code 01:59:11.928 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 953867 MB offset 2048 01:59:11.989 Disk 0 scanning C:\Windows\system32\drivers 01:59:22.986 Service scanning 01:59:37.488 Service RemoteAccess C:\Windows\SysWOW64\mprdin.dll **INFECTED** Win32:Sirefef-YF [Trj] 01:59:43.893 Modules scanning 01:59:43.900 Disk 0 trace - called modules: 01:59:43.923 ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys 01:59:43.927 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80071b8790] 01:59:44.261 3 CLASSPNP.SYS[fffffa6000bb0c33] -> nt!IofCallDriver -> [0xfffffa80061134e0] 01:59:44.266 5 acpi.sys[fffffa60008fffde] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800609a940] 01:59:56.901 AVAST engine scan C:\Windows 02:00:14.708 AVAST engine scan C:\Windows\system32 02:04:32.913 AVAST engine scan C:\Windows\system32\drivers 02:05:04.200 AVAST engine scan C:\Users\Owner 02:08:20.792 Verifying 02:08:30.812 Disk 0 Windows 600 MBR fixed successfully 02:08:45.475 Disk 0 MBR has been saved successfully to "C:\Users\Owner\Desktop\MBR.dat" 02:08:45.483 The log file has been saved successfully to "C:\Users\Owner\Desktop\aswMBR.txt"
The finished scan. aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-06-26 01:57:55 —————————– 01:57:55.677 OS Version: Windows x64 6.0.6002 Service Pack 2 01:57:55.677 Number of processors: 2 586 0x170A 01:57:55.678 ComputerName: OWNER-PC UserName: Owner 01:58:03.642 Initialize success 01:59:06.597 AVAST engine defs: 12062501 01:59:11.820 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 01:59:11.822 Disk 0 Vendor: ST1000DM003-9YN162 CC4D Size: 953869MB BusType: 3 01:59:11.915 Disk 0 MBR read successfully 01:59:11.918 Disk 0 MBR scan 01:59:11.922 Disk 0 Windows VISTA default MBR code 01:59:11.928 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 953867 MB offset 2048 01:59:11.989 Disk 0 scanning C:\Windows\system32\drivers 01:59:22.986 Service scanning 01:59:37.488 Service RemoteAccess C:\Windows\SysWOW64\mprdin.dll **INFECTED** Win32:Sirefef-YF [Trj] 01:59:43.893 Modules scanning 01:59:43.900 Disk 0 trace - called modules: 01:59:43.923 ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys 01:59:43.927 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80071b8790] 01:59:44.261 3 CLASSPNP.SYS[fffffa6000bb0c33] -> nt!IofCallDriver -> [0xfffffa80061134e0] 01:59:44.266 5 acpi.sys[fffffa60008fffde] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800609a940] 01:59:56.901 AVAST engine scan C:\Windows 02:00:14.708 AVAST engine scan C:\Windows\system32 02:04:32.913 AVAST engine scan C:\Windows\system32\drivers 02:05:04.200 AVAST engine scan C:\Users\Owner 02:08:20.792 Verifying 02:08:30.812 Disk 0 Windows 600 MBR fixed successfully 02:08:45.475 Disk 0 MBR has been saved successfully to "C:\Users\Owner\Desktop\MBR.dat" 02:08:45.483 The log file has been saved successfully to "C:\Users\Owner\Desktop\aswMBR.txt" 02:13:23.689 AVAST engine scan C:\ProgramData 02:15:46.321 Scan finished successfully 02:17:18.471 Verifying 02:17:28.487 Disk 0 Windows 600 MBR fixed successfully 02:17:46.800 Disk 0 MBR has been saved successfully to "C:\Users\Owner\Desktop\MBR.dat" 02:17:46.806 The log file has been saved successfully to "C:\Users\Owner\Desktop\aswMBR2.txt"
Hi jasons805,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

It appears that you have also ran ComboFix. Can you please post the log? It should be found at C:\ComboFix.txt
Thanks for the reply. I did run combo fix before, but can't seem to find that log. I tried runing it again but it seems to freeze up. I disabled AVG. I am going to redl combofix and try again. I ran it again and it seems to run then close after about 30 secs. looks like it may load but just seems to close out.
I do have an OTL log I can post

OTL logfile created on: 6/26/2012 1:54:22 PM - Run 1
OTL by OldTimer - Version 3.2.53.0 Folder = C:\Users\Owner\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16443)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.99 Gb Total Physical Memory | 3.81 Gb Available Physical Memory | 63.66% Memory free
12.14 Gb Paging File | 9.95 Gb Available in Paging File | 81.98% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.51 Gb Total Space | 577.02 Gb Free Space | 61.95% Space Free | Partition Type: NTFS
Drive I: | 596.02 Gb Total Space | 17.93 Gb Free Space | 3.01% Space Free | Partition Type: FAT32
Drive J: | 1862.98 Gb Total Space | 1216.37 Gb Free Space | 65.29% Space Free | Partition Type: NTFS

Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgcfgex.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
PRC - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\CAntiVirusCOM.dll ()
MOD - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\CFirewallCOM.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (AERTFilters) – C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)
SRV - (RemoteAccess) – C:\Windows\SysWOW64\mprdin.dll ()
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Fabs) – C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (nmservice) – C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (AVGIDSHA) – C:\Windows\SysNative\DRIVERS\avgidsha.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\DRIVERS\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\DRIVERS\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\DRIVERS\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\DRIVERS\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\DRIVERS\avgidsfiltera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\DRIVERS\avgidsdrivera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (RTL8169) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek )
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (purendis) – C:\Windows\SysNative\DRIVERS\purendis.sys (Cisco Systems, Inc.)
DRV:64bit: - (pnarp) – C:\Windows\SysNative\DRIVERS\pnarp.sys (Cisco Systems, Inc.)
DRV:64bit: - (WUSB54GCv3) – C:\Windows\SysNative\DRIVERS\WUSB54GCv3.sys (Ralink Technology Corp.)
DRV:64bit: - (igfx) – C:\Windows\SysNative\DRIVERS\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (VST64_DPV) – C:\Windows\SysNative\DRIVERS\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) – C:\Windows\SysNative\DRIVERS\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (VST64HWBS2) – C:\Windows\SysNative\DRIVERS\VSTBS26.SYS (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_2_202_228.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.0: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_228.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012/06/11 09:51:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files (x86)\AVG\AVG2012\Firefox\DoNotTrack\ [2012/04/27 09:22:46 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/05/24 20:30:25 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2012/04/11 16:38:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2012/04/11 16:21:08 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/04/11 16:21:08 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
[2012/03/13 00:39:39 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/03/13 00:38:32 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/03/13 00:38:32 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\19.0.1084.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\19.0.1084.56\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\19.0.1084.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_228.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Owner\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: AVG Safe Search = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\
CHR - Extension: AVG Do Not Track = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.0.0.2166_0\
CHR - Extension: Gmail = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/06/25 20:51:44 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Linksys Wireless Manager] C:\Program Files (x86)\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe (Linksys, LLC)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [nmctxth] C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [TrayServer] C:\Program Files (x86)\MAGIX\Movie_Edit_Pro_15_Plus_Download_version\TrayServer.exe (MAGIX AG)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9:64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16:64bit: - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8C91F51D-07B0-4519-8383-6C6ED5367944}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D554E48C-57A3-4F02-BF4C-44149732DBB9}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\amd64\puresp4.dll (Cisco Systems, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Owner\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Owner\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/10/28 09:49:48 | 000,000,000 | —D | M] - I:\autorun – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/06/26 13:44:17 | 000,596,992 | —- | C] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2012/06/26 05:21:06 | 000,000,000 | -HSD | C] – C:\Windows\SysNative\%APPDATA%
[2012/06/26 01:36:07 | 000,607,260 | R— | C] (Swearware) – C:\Users\Owner\Desktop\dds.com
[2012/06/26 01:36:01 | 004,731,392 | —- | C] (AVAST Software) – C:\Users\Owner\Desktop\aswMBR.exe
[2012/06/26 01:29:07 | 000,000,000 | –SD | C] – C:\ComboFix
[2012/06/26 00:39:08 | 000,000,000 | —D | C] – C:\sh4ldr
[2012/06/26 00:39:08 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2012/06/26 00:38:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2012/06/26 00:29:20 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/06/26 00:27:25 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\DriverCure
[2012/06/26 00:27:24 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\SpeedyPC Software
[2012/06/26 00:27:00 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedyPC Software
[2012/06/26 00:26:56 | 000,000,000 | —D | C] – C:\ProgramData\SpeedyPC Software
[2012/06/26 00:26:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\SpeedyPC Software
[2012/06/26 00:26:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\SpeedyPC Software
[2012/06/25 23:03:07 | 000,684,240 | —- | C] (Webroot) – C:\Users\Owner\Desktop\wsainstall.exe
[2012/06/25 21:16:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2012/06/25 20:54:08 | 000,000,000 | —D | C] – C:\Windows\temp
[2012/06/25 20:54:08 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\temp
[2012/06/25 19:53:43 | 002,128,472 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Owner\Desktop\TDSSKiller (2).exe
[2012/06/25 19:53:43 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\tdsskiller (2)
[2012/06/24 20:10:54 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\june16
[2012/06/21 21:20:33 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\june15
[2012/06/21 01:11:07 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/06/21 01:11:07 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/06/21 01:11:07 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/06/21 01:11:01 | 000,000,000 | —D | C] – C:\Qoobox
[2012/06/21 01:10:52 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012/06/21 01:05:12 | 004,569,239 | R— | C] (Swearware) – C:\Users\Owner\Desktop\ComboFix.exe
[2012/06/20 20:32:13 | 002,127,960 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Owner\Desktop\TDSSKiller.exe
[2012/06/20 20:32:13 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\tdsskiller (1)
[2012/06/20 20:14:49 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/06/20 20:14:49 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/06/20 20:14:49 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/06/20 20:14:25 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/06/20 20:14:25 | 000,577,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuapi.dll
[2012/06/20 20:14:25 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/06/20 20:14:25 | 000,088,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wudriver.dll
[2012/06/20 20:14:25 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/06/20 20:14:25 | 000,035,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wups.dll
[2012/06/20 20:14:15 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/06/20 20:14:15 | 000,171,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuwebv.dll
[2012/06/20 20:14:15 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2012/06/20 20:14:15 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuapp.exe
[2012/06/19 21:58:27 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\dub140songs
[2012/06/19 21:41:15 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\June14
[2012/06/18 22:16:01 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\june 13 dub140
[2012/06/17 20:39:11 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\june12
[2012/06/16 03:11:39 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/06/16 03:11:39 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/06/16 03:11:38 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/06/16 03:11:38 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/06/16 03:11:38 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/06/16 03:11:38 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/06/16 03:11:38 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/06/16 03:11:38 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/06/16 03:11:37 | 002,311,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/06/16 03:11:37 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/06/16 03:11:37 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/06/16 03:11:36 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/06/16 03:11:36 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/06/15 20:41:26 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\june11a
[2012/06/15 20:21:39 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\june11
[2012/06/15 02:26:40 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\SUPERAntiSpyware.com
[2012/06/15 02:26:04 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2012/06/15 02:26:04 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2012/06/15 01:30:47 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2012/06/11 21:33:14 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\june9
[2012/06/11 09:51:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2012/06/09 20:59:28 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\june8
[2012/06/04 22:01:03 | 000,955,848 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\npDeployJava1.dll
[2012/06/04 22:01:03 | 000,839,112 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2012/06/04 22:01:03 | 000,268,744 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2012/06/04 22:00:30 | 000,189,384 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2012/06/04 22:00:30 | 000,188,872 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2012/06/04 22:00:10 | 000,000,000 | —D | C] – C:\Program Files\Java
[2012/06/01 22:33:58 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\june1
[2012/06/01 10:30:58 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\pete
[2012/05/31 21:34:32 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\may25
[2012/05/30 16:34:57 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\may24
[2012/05/29 20:14:15 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\may23a
[2012/05/28 20:48:49 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\may22
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

File not found – C:\Windows\SysNative\
[2012/06/26 13:43:46 | 000,596,992 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2012/06/26 13:43:01 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/26 13:04:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-227403830-1489361018-169835606-1000UA.job
[2012/06/26 13:00:51 | 000,003,760 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/26 13:00:51 | 000,003,760 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/26 09:53:03 | 100,725,600 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/06/26 09:00:57 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/06/26 02:51:53 | 000,161,280 | —- | M] () – C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/06/26 02:17:46 | 000,000,512 | —- | M] () – C:\Users\Owner\Desktop\MBR.dat
[2012/06/26 01:35:56 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\Owner\Desktop\aswMBR.exe
[2012/06/26 01:34:46 | 000,607,260 | R— | M] (Swearware) – C:\Users\Owner\Desktop\dds.com
[2012/06/26 01:33:41 | 000,458,240 | —- | M] () – C:\Users\Owner\Desktop\CKScanner.exe
[2012/06/26 01:28:14 | 000,703,388 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/26 01:28:14 | 000,604,264 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/26 01:28:14 | 000,103,964 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/06/26 01:21:38 | 000,000,492 | —- | M] () – C:\Windows\tasks\SpeedyPC Registration3.job
[2012/06/26 01:21:38 | 000,000,464 | —- | M] () – C:\Windows\tasks\SpeedyPC Update Version3.job
[2012/06/26 01:21:38 | 000,000,420 | —- | M] () – C:\Windows\tasks\SpeedyPC Pro.job
[2012/06/26 01:17:30 | 004,569,239 | R— | M] (Swearware) – C:\Users\Owner\Desktop\ComboFix.exe
[2012/06/26 00:44:31 | 000,020,454 | —- | M] () – C:\Users\Owner\Documents\cc_20120626_004420.reg
[2012/06/26 00:27:00 | 000,001,030 | —- | M] () – C:\Users\Owner\Desktop\SpeedyPC Pro.lnk
[2012/06/25 23:02:41 | 000,684,240 | —- | M] (Webroot) – C:\Users\Owner\Desktop\wsainstall.exe
[2012/06/25 20:51:44 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012/06/25 19:53:24 | 002,109,806 | —- | M] () – C:\Users\Owner\Desktop\tdsskiller (2).zip
[2012/06/22 19:04:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-227403830-1489361018-169835606-1000Core.job
[2012/06/22 17:42:50 | 000,316,396 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/06/21 23:25:44 | 012,148,675 | —- | M] () – C:\Users\Owner\Desktop\18 An American Trilogy.m4a
[2012/06/20 21:11:20 | 002,128,472 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Owner\Desktop\TDSSKiller (2).exe
[2012/06/20 21:05:01 | 000,569,120 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/20 20:35:44 | 000,001,115 | —- | M] () – C:\Users\Owner\Desktop\Spybot - Search & Destroy.lnk
[2012/06/20 20:31:59 | 002,109,032 | —- | M] () – C:\Users\Owner\Desktop\tdsskiller (1).zip
[2012/06/15 15:15:16 | 002,127,960 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Owner\Desktop\TDSSKiller.exe
[2012/06/12 01:05:30 | 000,002,042 | —- | M] () – C:\Users\Owner\Desktop\Google Chrome.lnk
[2012/06/12 01:05:30 | 000,002,004 | —- | M] () – C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/06/11 09:51:17 | 000,000,872 | —- | M] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2012/06/04 22:00:12 | 000,955,848 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\npDeployJava1.dll
[2012/06/04 22:00:12 | 000,839,112 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2012/06/04 22:00:12 | 000,268,744 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2012/06/04 22:00:12 | 000,189,384 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2012/06/04 22:00:12 | 000,188,872 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2012/06/03 14:24:50 | 000,040,222 | —- | M] () – C:\Users\Owner\mdy.jpg
[2012/06/02 18:19:46 | 000,038,424 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/06/02 18:19:42 | 000,057,880 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/06/02 18:19:42 | 000,044,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/06/02 18:19:32 | 000,035,864 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wups.dll
[2012/06/02 18:19:23 | 000,701,976 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/06/02 18:19:23 | 000,577,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wuapi.dll
[2012/06/02 18:15:31 | 002,622,464 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/06/02 18:15:08 | 000,099,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/06/02 18:12:13 | 000,088,576 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wudriver.dll
[2012/06/02 15:19:42 | 000,186,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/06/02 15:19:42 | 000,171,904 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wuwebv.dll
[2012/06/02 15:15:12 | 000,036,864 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2012/06/02 15:12:20 | 000,033,792 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wuapp.exe
[2012/06/01 19:23:38 | 007,495,739 | —- | M] () – C:\Users\Owner\Desktop\12-Let-The-Church-Say-Amen.mp3
[2012/05/28 03:21:45 | 000,000,446 | —- | M] () – C:\Windows\SysWow64\mprdin.ocx
[2012/05/28 03:21:39 | 001,800,704 | —- | M] () – C:\Windows\SysWow64\mprdin.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

File not found – C:\Windows\SysNative\
[2012/06/26 05:17:52 | 000,022,016 | —- | C] () – C:\Windows\Installer\{e5220a19-6f58-87a6-8d09-f4accbc76eae}\U\800000cb.@
[2012/06/26 05:17:50 | 000,016,896 | —- | C] () – C:\Windows\Installer\{e5220a19-6f58-87a6-8d09-f4accbc76eae}\U\80000000.@
[2012/06/26 05:17:50 | 000,001,648 | —- | C] () – C:\Windows\Installer\{e5220a19-6f58-87a6-8d09-f4accbc76eae}\U\00000001.@
[2012/06/26 02:08:45 | 000,000,512 | —- | C] () – C:\Users\Owner\Desktop\MBR.dat
[2012/06/26 01:34:01 | 000,458,240 | —- | C] () – C:\Users\Owner\Desktop\CKScanner.exe
[2012/06/26 00:44:25 | 000,020,454 | —- | C] () – C:\Users\Owner\Documents\cc_20120626_004420.reg
[2012/06/26 00:30:20 | 000,000,492 | —- | C] () – C:\Windows\tasks\SpeedyPC Registration3.job
[2012/06/26 00:27:00 | 000,001,030 | —- | C] () – C:\Users\Owner\Desktop\SpeedyPC Pro.lnk
[2012/06/26 00:26:59 | 000,000,464 | —- | C] () – C:\Windows\tasks\SpeedyPC Update Version3.job
[2012/06/26 00:26:58 | 000,000,420 | —- | C] () – C:\Windows\tasks\SpeedyPC Pro.job
[2012/06/25 19:53:33 | 002,109,806 | —- | C] () – C:\Users\Owner\Desktop\tdsskiller (2).zip
[2012/06/21 23:27:14 | 012,148,675 | —- | C] () – C:\Users\Owner\Desktop\18 An American Trilogy.m4a
[2012/06/21 01:11:07 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/06/21 01:11:07 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/06/21 01:11:07 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/06/21 01:11:07 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/06/21 01:11:07 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/06/20 20:35:44 | 000,001,115 | —- | C] () – C:\Users\Owner\Desktop\Spybot - Search & Destroy.lnk
[2012/06/20 20:32:07 | 002,109,032 | —- | C] () – C:\Users\Owner\Desktop\tdsskiller (1).zip
[2012/06/17 14:34:42 | 007,495,739 | —- | C] () – C:\Users\Owner\Desktop\12-Let-The-Church-Say-Amen.mp3
[2012/06/03 14:24:48 | 000,040,222 | —- | C] () – C:\Users\Owner\mdy.jpg
[2012/05/28 03:21:45 | 000,000,446 | —- | C] () – C:\Windows\SysWow64\mprdin.ocx
[2012/05/28 03:21:39 | 001,800,704 | —- | C] () – C:\Windows\SysWow64\mprdin.dll
[2012/05/26 22:44:45 | 000,073,929 | —- | C] () – C:\Users\Owner\565767575 copy.jpg
[2012/04/14 23:42:28 | 000,645,632 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2012/04/14 23:42:28 | 000,240,640 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2012/04/14 22:15:07 | 000,006,211 | —- | C] () – C:\Windows\mgxoschk.ini
[2012/04/13 13:46:00 | 001,790,464 | —- | C] () – C:\Windows\SysWow64\ipnathlp.dll
[2012/04/12 19:30:24 | 000,161,280 | —- | C] () – C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/04/12 17:52:18 | 000,001,366 | —- | C] () – C:\Windows\checkip.dat
[2012/04/11 13:41:25 | 000,002,048 | -HS- | C] () – C:\Windows\Installer\{e5220a19-6f58-87a6-8d09-f4accbc76eae}\@
[2012/04/11 13:41:25 | 000,002,048 | -HS- | C] () – C:\Users\Owner\AppData\Local\{e5220a19-6f58-87a6-8d09-f4accbc76eae}\@
[2012/04/11 12:57:12 | 000,000,732 | —- | C] () – C:\Users\Owner\AppData\Local\d3d9caps64.dat

========== LOP Check ==========

[2012/04/12 22:42:21 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\ACD Systems
[2012/04/13 01:40:49 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\AVG2012
[2012/04/11 16:35:53 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Canneverbe Limited
[2012/06/26 00:27:25 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\DriverCure
[2012/04/14 22:19:45 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\MAGIX
[2012/06/26 00:27:24 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\SpeedyPC Software
[2012/06/26 03:22:50 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\uTorrent
[2012/04/11 13:11:17 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\WinBatch
[2012/04/13 13:53:49 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Xilisoft
[2012/06/26 01:09:06 | 000,015,782 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2012/06/26 01:21:38 | 000,000,420 | —- | M] () – C:\Windows\Tasks\SpeedyPC Pro.job
[2012/06/26 01:21:38 | 000,000,492 | —- | M] () – C:\Windows\Tasks\SpeedyPC Registration3.job
[2012/06/26 01:21:38 | 000,000,464 | —- | M] () – C:\Windows\Tasks\SpeedyPC Update Version3.job

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2009/04/11 12:23:29 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2012/04/11 16:31:39 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2012/06/26 01:21:33 | 2449,756,159 | -HS- | M] () – C:\pagefile.sys
[2012/06/14 22:50:36 | 000,110,624 | —- | M] () – C:\TDSSKiller.2.7.39.0_14.06.2012_22.50.02_log.txt
[2012/06/15 01:30:51 | 000,217,556 | —- | M] () – C:\TDSSKiller.2.7.39.0_15.06.2012_01.28.46_log.txt
[2012/06/20 20:33:40 | 000,110,624 | —- | M] () – C:\TDSSKiller.2.7.40.0_20.06.2012_20.32.30_log.txt
[2012/06/20 21:03:07 | 000,431,292 | —- | M] () – C:\TDSSKiller.2.7.40.0_20.06.2012_21.00.33_log.txt
[2012/06/25 19:53:20 | 000,000,348 | —- | M] () – C:\TDSSKiller.2.7.40.0_25.06.2012_19.53.17_log.txt
[2012/06/25 19:54:41 | 000,110,154 | —- | M] () – C:\TDSSKiller.2.7.41.0_25.06.2012_19.54.01_log.txt

< %systemroot%\Fonts\*.com >
[2006/11/02 11:06:41 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 11:06:41 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 11:06:41 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/04/11 12:26:01 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 17:35:48 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 23:21:59 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/04/12 19:56:01 | 000,000,286 | -HS- | M] () – C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/06/26 01:35:56 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\Owner\Desktop\aswMBR.exe
[2012/06/26 01:33:41 | 000,458,240 | —- | M] () – C:\Users\Owner\Desktop\CKScanner.exe
[2012/06/26 01:17:30 | 004,569,239 | R— | M] (Swearware) – C:\Users\Owner\Desktop\ComboFix.exe
[2012/06/26 13:43:46 | 000,596,992 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2012/06/20 21:11:20 | 002,128,472 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Owner\Desktop\TDSSKiller (2).exe
[2012/06/15 15:15:16 | 002,127,960 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Owner\Desktop\TDSSKiller.exe
[2012/06/25 23:02:41 | 000,684,240 | —- | M] (Webroot) – C:\Users\Owner\Desktop\wsainstall.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >
jasons805,

Don't re-run ComboFix at this point. You appear to have a nasty Siref infection and it will mess with your security settings.

Your computer appears to have been infected by a backdoor trojan. These programs have the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.


uTorrent
You have uTorrent, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. Specifically, the Siref infection that you have almost always comes from downloading pirated software. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm


I would recommend that you uninstall Limewire, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

Double click on OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes

:OTL
SRV - (RemoteAccess) – C:\Windows\SysWOW64\mprdin.dll ()
[2012/05/28 03:21:45 | 000,000,446 | —- | M] () – C:\Windows\SysWow64\mprdin.ocx
[2012/05/28 03:21:39 | 001,800,704 | —- | M] () – C:\Windows\SysWow64\mprdin.dll
[2012/06/26 05:17:52 | 000,022,016 | —- | C] () – C:\Windows\Installer\{e5220a19-6f58-87a6-8d09-f4accbc76eae}\U\800000cb.@
[2012/06/26 05:17:50 | 000,016,896 | —- | C] () – C:\Windows\Installer\{e5220a19-6f58-87a6-8d09-f4accbc76eae}\U\80000000.@
[2012/06/26 05:17:50 | 000,001,648 | —- | C] () – C:\Windows\Installer\{e5220a19-6f58-87a6-8d09-f4accbc76eae}\U\00000001.@
[2012/04/11 13:41:25 | 000,002,048 | -HS- | C] () – C:\Windows\Installer\{e5220a19-6f58-87a6-8d09-f4accbc76eae}\@
[2012/04/11 13:41:25 | 000,002,048 | -HS- | C] () – C:\Users\Owner\AppData\Local\{e5220a19-6f58-87a6-8d09-f4accbc76eae}\@

:Reg

:Files
C:\Windows\Installer\{e5220a19-6f58-87a6-8d09-f4accbc76eae}
C:\Users\Owner\AppData\Local\{e5220a19-6f58-87a6-8d09-f4accbc76eae}
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log.
Here is the new log All processes killed ========== PROCESSES ========== ========== OTL ========== Service RemoteAccess stopped successfully! Service RemoteAccess deleted successfully! C:\Windows\SysWOW64\mprdin.dll moved successfully. C:\Windows\SysWOW64\mprdin.ocx moved successfully. File C:\Windows\SysWow64\mprdin.dll not found. C:\Windows\Installer\{e5220a19-6f58-87a6-8d09-f4accbc76eae}\U\800000cb.@ moved successfully. C:\Windows\Installer\{e5220a19-6f58-87a6-8d09-f4accbc76eae}\U\80000000.@ moved successfully. C:\Windows\Installer\{e5220a19-6f58-87a6-8d09-f4accbc76eae}\U\00000001.@ moved successfully. File C:\Windows\Installer\{e5220a19-6f58-87a6-8d09-f4accbc76eae}\@ not found. C:\Users\Owner\AppData\Local\{e5220a19-6f58-87a6-8d09-f4accbc76eae}\@ moved successfully. ========== REGISTRY ========== ========== FILES ========== C:\Windows\Installer\{e5220a19-6f58-87a6-8d09-f4accbc76eae}\U folder moved successfully. C:\Windows\Installer\{e5220a19-6f58-87a6-8d09-f4accbc76eae}\L folder moved successfully. Folder move failed. C:\Windows\Installer\{e5220a19-6f58-87a6-8d09-f4accbc76eae} scheduled to be moved on reboot. C:\Users\Owner\AppData\Local\{e5220a19-6f58-87a6-8d09-f4accbc76eae}\U folder moved successfully. C:\Users\Owner\AppData\Local\{e5220a19-6f58-87a6-8d09-f4accbc76eae}\L folder moved successfully. C:\Users\Owner\AppData\Local\{e5220a19-6f58-87a6-8d09-f4accbc76eae} folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Owner ->Temp folder emptied: 98249145 bytes ->Temporary Internet Files folder emptied: 61378564 bytes ->Java cache emptied: 70539 bytes ->FireFox cache emptied: 11518976 bytes ->Google Chrome cache emptied: 355042337 bytes ->Flash cache emptied: 5632 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 1713869 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 1394 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 178885792 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 674.00 mb OTL by OldTimer - Version 3.2.53.0 log created on 06282012_130503 Files\Folders moved on Reboot… C:\Windows\Installer\{e5220a19-6f58-87a6-8d09-f4accbc76eae}\U folder moved successfully. C:\Windows\Installer\{e5220a19-6f58-87a6-8d09-f4accbc76eae} folder moved successfully. File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W00STIHS\adCAPHR7V7.htm not found! File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W00STIHS\Arancini-di-Riso-(Cheese-Filled-Risotto-Croquettes[1].htm not found! C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W00STIHS\iframe_adspotCAH1QOPX.htm moved successfully. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W00STIHS\iframe_adspotCAN1Q5K6.htm moved successfully. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W00STIHS\iframe_adspotCAR0FIYB.htm moved successfully. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W00STIHS\tr-clk[5].htm moved successfully. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O01NSVW2\iframe_adspotCARXRA7Y.htm moved successfully. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O01NSVW2\iframe_adspotCAZXJU76.htm moved successfully. PendingFileRenameOperations files… File C:\Windows\Installer\{e5220a19-6f58-87a6-8d09-f4accbc76eae} not found! File C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W00STIHS\adCAPHR7V7.htm not found! File C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W00STIHS\Arancini-di-Riso-(Cheese-Filled-Risotto-Croquettes[1].htm not found! File C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W00STIHS\iframe_adspotCAH1QOPX.htm not found! File C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W00STIHS\iframe_adspotCAN1Q5K6.htm not found! File C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W00STIHS\iframe_adspotCAR0FIYB.htm not found! File C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W00STIHS\tr-clk[5].htm not found! File C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O01NSVW2\iframe_adspotCARXRA7Y.htm not found! File C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O01NSVW2\iframe_adspotCAZXJU76.htm not found! Registry entries deleted on Reboot…
I noticed my Microsoft firewall is not working. Not sure if this is related or not. I installed Zone Alarm firewall and have it running now.

I noticed my Microsoft firewall is not working. Not sure if this is related or not.
I installed Zone Alarm firewall and have it running now.


That is a symptom of this infection. Often "victims" also get Windows Defender corruption warnings.

Now that we've hopefully taken the teeth out of the tiger… please drag your copy of ComboFix to your recycle bin and then download a fresh copy.

Go ahead and try to run it - being sure to run as Administrator - and post the resultant log.
I ran combo fix and it went till about the end and after it got to 50 stayed on the windows services file infect trying to fix. It was taking about an hour/45mins so I stopped it to ask if that was normal. Have an attached screen shot. PS a quick note windows did do an update after a couple of reboots this was a couple hours after running OTL.

Attachments:

The siref infection corrupts system files… but not always the same ones. This is the main reason I wanted to run ComboFix - to see if it could identify ones that are corrupted. Please see if you have a C: combofix.txt file. If you do… please post it. If you don't… then please try running comboFix again and see if it will complete. If it "hangs" for over 2 hours… then go ahead and stop it again and let me know.
I got it to finish here is my log. ComboFix 12-06-28.03 - Owner 06/28/2012 21:02:43.5.2 - x64 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.6132.2789 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} FW: ZoneAlarm Free Firewall Firewall *Disabled* {E6380B7E-D4B2-19F1-083E-56486607704B} SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\system32\Services.exe . . . is infected!! . . ((((((((((((((((((((((((( Files Created from 2012-05-28 to 2012-06-29 ))))))))))))))))))))))))))))))) . . 2012-06-29 01:34 . 2012-06-29 01:34 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-06-28 18:47 . 2012-06-28 18:47 ——– d—–w- c:\users\Owner\AppData\Roaming\CheckPoint 2012-06-28 18:47 . 2012-06-28 18:47 ——– d—–w- c:\program files\CheckPoint 2012-06-28 18:46 . 2010-04-06 08:34 345984 —-a-w- c:\windows\system32\drivers\netio.sys 2012-06-28 18:44 . 2012-06-28 18:46 ——– d—–w- c:\program files (x86)\CheckPoint 2012-06-28 18:44 . 2012-06-28 18:44 ——– d—–w- c:\programdata\CheckPoint 2012-06-28 18:29 . 2012-06-28 18:29 ——– d—–w- c:\users\Owner\AppData\Local\ElevatedDiagnostics 2012-06-28 17:05 . 2012-06-28 17:05 ——– d—–w- C:\_OTL 2012-06-26 09:21 . 2012-06-26 09:21 ——– d-sh–w- c:\windows\system32\%APPDATA% 2012-06-26 04:39 . 2012-06-26 05:25 ——– d—–w- C:\sh4ldr 2012-06-26 04:39 . 2012-06-26 04:39 ——– d—–w- c:\program files\Enigma Software Group 2012-06-26 04:38 . 2012-06-26 04:38 ——– d—–w- c:\program files (x86)\Common Files\Wise Installation Wizard 2012-06-26 04:27 . 2012-06-26 04:27 ——– d—–w- c:\users\Owner\AppData\Roaming\DriverCure 2012-06-26 04:27 . 2012-06-26 04:27 ——– d—–w- c:\users\Owner\AppData\Roaming\SpeedyPC Software 2012-06-26 04:26 . 2012-06-26 04:26 ——– d—–w- c:\programdata\SpeedyPC Software 2012-06-26 04:26 . 2012-06-26 04:26 ——– d—–w- c:\program files (x86)\SpeedyPC Software 2012-06-26 04:26 . 2012-06-26 04:26 ——– d—–w- c:\program files (x86)\Common Files\SpeedyPC Software 2012-06-26 01:16 . 2012-06-26 01:16 ——– d—–w- c:\program files (x86)\ESET 2012-06-26 00:54 . 2012-06-29 01:39 ——– d—–w- c:\users\Owner\AppData\Local\temp 2012-06-16 07:11 . 2012-05-18 02:51 174200 —-a-w- c:\program files\Internet Explorer\sqmapi.dll 2012-06-15 15:21 . 2012-05-15 05:41 8955792 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A42FB8D3-25F6-46E3-A4E8-6007F953CBA6}\mpengine.dll 2012-06-15 15:18 . 2012-05-01 14:29 209920 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-06-15 15:18 . 2012-05-15 20:15 2767360 —-a-w- c:\windows\system32\win32k.sys 2012-06-15 06:26 . 2012-06-15 06:26 ——– d—–w- c:\users\Owner\AppData\Roaming\SUPERAntiSpyware.com 2012-06-15 06:26 . 2012-06-15 14:57 ——– d—–w- c:\program files\SUPERAntiSpyware 2012-06-15 06:26 . 2012-06-15 06:26 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2012-06-15 05:30 . 2012-06-21 01:02 ——– d—–w- C:\TDSSKiller_Quarantine 2012-06-05 02:01 . 2012-06-05 02:00 955848 —-a-w- c:\windows\system32\npDeployJava1.dll 2012-06-05 02:01 . 2012-06-05 02:00 839112 —-a-w- c:\windows\system32\deployJava1.dll 2012-06-05 02:00 . 2012-06-15 14:54 ——– d—–w- c:\program files\Java . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-04-19 08:50 . 2012-04-19 08:50 28480 —-a-w- c:\windows\system32\drivers\avgidsha.sys 2012-04-13 17:46 . 2012-04-13 17:46 1790464 —-a-w- c:\windows\SysWow64\ipnathlp.dll 2012-04-11 21:21 . 2012-04-11 21:21 525792 —-a-w- c:\windows\DIFxAPI.dll 2012-04-11 20:21 . 2012-04-11 20:21 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll 2012-04-11 20:20 . 2012-04-11 20:20 70304 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-04-11 20:20 . 2012-04-11 20:20 418464 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-04-11 18:40 . 2012-04-11 18:40 86528 —-a-w- c:\windows\SysWow64\iesysprep.dll 2012-04-11 18:40 . 2012-04-11 18:40 76800 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2012-04-11 18:40 . 2012-04-11 18:40 74752 —-a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2012-04-11 18:40 . 2012-04-11 18:40 63488 —-a-w- c:\windows\SysWow64\tdc.ocx 2012-04-11 18:40 . 2012-04-11 18:40 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll 2012-04-11 18:40 . 2012-04-11 18:40 367104 —-a-w- c:\windows\SysWow64\html.iec 2012-04-11 18:40 . 2012-04-11 18:40 161792 —-a-w- c:\windows\SysWow64\msls31.dll 2012-04-11 18:40 . 2012-04-11 18:40 74752 —-a-w- c:\windows\SysWow64\iesetup.dll 2012-04-11 18:40 . 2012-04-11 18:40 420864 —-a-w- c:\windows\SysWow64\vbscript.dll 2012-04-11 18:40 . 2012-04-11 18:40 35840 —-a-w- c:\windows\SysWow64\imgutil.dll 2012-04-11 18:40 . 2012-04-11 18:40 23552 —-a-w- c:\windows\SysWow64\licmgr10.dll 2012-04-11 18:40 . 2012-04-11 18:40 152064 —-a-w- c:\windows\SysWow64\wextract.exe 2012-04-11 18:40 . 2012-04-11 18:40 150528 —-a-w- c:\windows\SysWow64\iexpress.exe 2012-04-11 18:40 . 2012-04-11 18:40 11776 —-a-w- c:\windows\SysWow64\mshta.exe 2012-04-11 18:40 . 2012-04-11 18:40 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll 2012-04-11 18:40 . 2012-04-11 18:40 101888 —-a-w- c:\windows\SysWow64\admparse.dll 2012-04-11 18:40 . 2012-04-11 18:40 91648 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2012-04-11 18:40 . 2012-04-11 18:40 89088 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2012-04-11 18:40 . 2012-04-11 18:40 49664 —-a-w- c:\windows\system32\imgutil.dll 2012-04-11 18:40 . 2012-04-11 18:40 48640 —-a-w- c:\windows\system32\mshtmler.dll 2012-04-11 18:40 . 2012-04-11 18:40 222208 —-a-w- c:\windows\system32\msls31.dll 2012-04-11 18:40 . 2012-04-11 18:40 135168 —-a-w- c:\windows\system32\IEAdvpack.dll 2012-04-11 18:40 . 2012-04-11 18:40 12288 —-a-w- c:\windows\system32\mshta.exe 2012-04-11 18:40 . 2012-04-11 18:40 114176 —-a-w- c:\windows\system32\admparse.dll 2012-04-11 18:40 . 2012-04-11 18:40 111616 —-a-w- c:\windows\system32\iesysprep.dll 2012-04-11 18:40 . 2012-04-11 18:40 85504 —-a-w- c:\windows\system32\iesetup.dll 2012-04-11 18:40 . 2012-04-11 18:40 76800 —-a-w- c:\windows\system32\tdc.ocx 2012-04-11 18:40 . 2012-04-11 18:40 603648 —-a-w- c:\windows\system32\vbscript.dll 2012-04-11 18:40 . 2012-04-11 18:40 448512 —-a-w- c:\windows\system32\html.iec 2012-04-11 18:40 . 2012-04-11 18:40 30720 —-a-w- c:\windows\system32\licmgr10.dll 2012-04-11 18:40 . 2012-04-11 18:40 165888 —-a-w- c:\windows\system32\iexpress.exe 2012-04-11 18:40 . 2012-04-11 18:40 160256 —-a-w- c:\windows\system32\wextract.exe 2012-04-04 19:56 . 2012-04-11 20:29 24904 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-04-03 08:22 . 2012-05-12 09:50 4699520 —-a-w- c:\windows\system32\ntoskrnl.exe . . ——- Sigcheck ——- Note: Unsigned files aren't necessarily malware. . [7] 2009-04-11 . 934E0B7D77FF78C18D9F8891221B6DE3 . 384512 . . [6.0.6002.18005] .. c:\windows\erdnt\cache64\services.exe [7] 2009-04-11 . 934E0B7D77FF78C18D9F8891221B6DE3 . 384512 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_2d69d4f782c83d8c\services.exe [-] 2009-04-11 . BC81150939BD52DBC7A08C245F1FB229 . 384512 . . [6.0.6000.16386] .. c:\windows\system32\services.exe . ((((((((((((((((((((((((((((( SnapShot@2012-06-21_05.22.00 ))))))))))))))))))))))))))))))))))))))))) . + 2008-01-21 03:20 . 2012-06-29 01:37 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2008-01-21 03:20 . 2012-06-21 05:19 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2008-01-21 03:20 . 2012-06-21 05:19 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2008-01-21 03:20 . 2012-06-29 01:37 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2008-01-21 03:20 . 2012-06-29 01:37 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2008-01-21 03:20 . 2012-06-21 05:19 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2008-01-21 02:23 . 2012-06-29 01:39 37182 c:\windows\system32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin + 2006-11-02 15:45 . 2012-06-29 01:39 69396 c:\windows\system32\WDI\BootPerformanceDiagnostics_SystemData.bin - 2012-04-11 17:43 . 2009-12-08 17:55 40448 c:\windows\system32\drivers\tcpipreg.sys + 2012-05-12 09:50 . 2012-03-29 14:22 40448 c:\windows\system32\drivers\tcpipreg.sys + 2012-06-20 09:41 . 2012-06-28 12:00 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\UserData\index.dat - 2012-06-20 09:41 . 2012-06-20 19:21 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\UserData\index.dat + 2012-06-15 12:58 . 2012-06-28 17:04 49152 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat + 2012-06-26 09:21 . 2012-06-28 17:04 16384 c:\windows\system32\%APPDATA%\Microsoft\Windows\IETldCache\index.dat + 2012-06-28 18:47 . 2012-06-28 18:47 28672 c:\windows\Installer\54bf47.msi + 2012-06-28 18:46 . 2012-06-28 18:46 41472 c:\windows\Installer\54bf40.msi - 2006-11-02 12:40 . 2012-04-12 23:04 86016 c:\windows\inf\infstrng.dat + 2006-11-02 12:40 . 2012-06-28 18:48 86016 c:\windows\inf\infstrng.dat + 2006-11-02 12:40 . 2012-06-28 18:48 86016 c:\windows\inf\infstor.dat - 2006-11-02 12:40 . 2012-04-12 23:04 86016 c:\windows\inf\infstor.dat + 2006-11-02 12:40 . 2012-06-28 18:48 51200 c:\windows\inf\infpub.dat - 2006-11-02 12:40 . 2012-04-12 23:04 51200 c:\windows\inf\infpub.dat + 2012-04-11 17:08 . 2012-06-29 01:39 7930 c:\windows\system32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-227403830-1489361018-169835606-1000_UserData.bin - 2012-06-21 05:19 . 2012-06-21 05:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-06-29 01:36 . 2012-06-29 01:36 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-06-29 01:36 . 2012-06-29 01:36 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2012-06-21 05:19 . 2012-06-21 05:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2012-06-21 01:05 . 2012-06-21 05:19 262144 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat + 2012-06-21 01:05 . 2012-06-29 01:37 262144 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat + 2012-04-13 10:23 . 2012-06-29 00:04 228540 c:\windows\system32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin - 2006-11-02 12:46 . 2012-06-21 01:12 604264 c:\windows\system32\perfh009.dat + 2006-11-02 12:46 . 2012-06-28 19:15 604264 c:\windows\system32\perfh009.dat - 2006-11-02 12:46 . 2012-06-21 01:12 103964 c:\windows\system32\perfc009.dat + 2006-11-02 12:46 . 2012-06-28 19:15 103964 c:\windows\system32\perfc009.dat + 2011-05-07 21:51 . 2011-05-07 21:51 448088 c:\windows\system32\DriverStore\FileRepository\vsdatant.inf_1832f70c\vsdatant.sys + 2011-05-07 21:51 . 2011-05-07 21:51 448088 c:\windows\system32\drivers\vsdatant.sys - 2006-11-02 15:17 . 2012-06-21 00:01 262144 c:\windows\system32\config\systemprofile\ntuser.dat + 2006-11-02 15:17 . 2012-06-25 23:15 262144 c:\windows\system32\config\systemprofile\ntuser.dat + 2012-04-11 19:40 . 2012-06-28 19:22 507904 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2012-04-11 18:42 . 2012-06-29 01:35 461428 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2012-04-11 18:42 . 2012-06-21 05:18 461428 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2012-04-11 21:04 . 2012-06-28 19:05 520084 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-227403830-1489361018-169835606-1000-12288.dat + 2012-05-12 09:50 . 2012-03-30 12:45 1422720 c:\windows\system32\drivers\tcpip.sys + 2012-04-11 19:40 . 2012-06-28 19:22 6127616 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2012-04-11 20:11 . 2012-06-29 01:35 1235572 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-227403830-1489361018-169835606-1000-8192.dat - 2012-04-17 02:32 . 2012-06-15 03:38 4516721 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-227403830-1489361018-169835606-1000-4096.dat + 2012-04-17 02:32 . 2012-06-26 05:09 4516721 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-227403830-1489361018-169835606-1000-4096.dat + 2012-04-17 02:32 . 2012-06-29 01:35 8137204 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-18-16384.dat + 2006-11-02 12:33 . 2012-06-28 19:06 10747904 c:\windows\system32\SMI\Store\Machine\schema.dat - 2006-11-02 12:33 . 2012-06-21 00:42 10747904 c:\windows\system32\SMI\Store\Machine\schema.dat + 2012-04-11 19:40 . 2012-06-28 19:22 16187392 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat . – Snapshot reset to current date – . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712] "nmctxth"="c:\program files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-12 642856] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-06 421736] "AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2012-04-05 2587008] "TrayServer"="c:\program files (x86)\MAGIX\Movie_Edit_Pro_15_Plus_Download_version\TrayServer.exe" [2008-11-13 90112] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-07-05 421888] "ZoneAlarm"="c:\program files (x86)\CheckPoint\ZoneAlarm\zatray.exe" [2012-06-21 73392] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Adobe Gamma Loader.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2012-4-12 113664] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart . R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-11 253600] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928] S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2008-09-25 88576] . . HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs Themes . Contents of the 'Scheduled Tasks' folder . 2012-06-29 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-11 20:20] . 2012-06-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-227403830-1489361018-169835606-1000Core.job - c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-12 22:59] . 2012-06-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-227403830-1489361018-169835606-1000UA.job - c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-12 22:59] . 2012-06-26 c:\windows\Tasks\SpeedyPC Pro.job - c:\program files (x86)\SpeedyPC Software\SpeedyPC\SpeedyPC.exe [2012-01-30 22:17] . 2012-06-28 c:\windows\Tasks\SpeedyPC Registration3.job - c:\windows\system32\rundll32.exe [2006-11-02 09:45] . 2012-06-26 c:\windows\Tasks\SpeedyPC Update Version3.job - c:\program files (x86)\Common Files\SpeedyPC Software\UUS3\SpeedyPC_Update3.exe [2012-01-30 22:17] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-05-28 151064] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-05-28 208920] "Persistence"="c:\windows\system32\igfxpers.exe" [2008-05-28 176152] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2008-11-04 6848544] "Linksys Wireless Manager"="c:\program files (x86)\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe" [2009-02-16 1358384] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local TCP: DhcpNameServer = 75.75.75.75 75.75.76.76 CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\epodx6qi.default\ . - - - - ORPHANS REMOVED - - - - . HKLM-Run-ISW - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.032" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.apd\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.apd" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.arw" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.bay" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.bw" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.cr2" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.crw" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.cs1" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.dcr" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.dcx" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djv\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.djv" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djvu\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.djvu" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.dng" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.erf" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.fff" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.fpx" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.hdr" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icn\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.icn" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.iff" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ilbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.ilbm" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.int\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.int" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inta\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.inta" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iw4\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.iw4" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.j2c" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.j2k" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jbr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.jbr" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.jif" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.jp2" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.jpc" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpk\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.jpk" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.jpx" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.kdc" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.lbm" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.mef" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.mos" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.mrw" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.nef" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nrw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.nrw" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.orf" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.pbm" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.pbr" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcd\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.pcd" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.pcx" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.pef" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.pgm" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pix\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.pix" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.ppm" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspbrush\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.pspbrush" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspimage\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.pspimage" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.raf" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.ras" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgb\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.rgb" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgba\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.rgba" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsb\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.rsb" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rw2\UserChoice] @Denied: (2) (S-1-5-21-227403830-1489361018-169835606-1000) @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.rw2" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rwl\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.rwl" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgi\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.sgi" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.sr2" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.srf" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.srw" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v50po\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.v50po" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v50pp\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.v50pp" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v50ppf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.v50ppf" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.wbm" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.xbm" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.xif" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.xmp" . [HKEY_USERS\S-1-5-21-227403830-1489361018-169835606-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 5.xpm" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}] @Denied: (A 2) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0] @="Shockwave Flash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] @Denied: (A 2) (Everyone) @="" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0] @="FlashBroker" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes] "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe c:\program files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe c:\program files (x86)\AVG\AVG2012\avgcfgex.exe . ************************************************************************** . Completion time: 2012-06-28 21:42:35 - machine was rebooted ComboFix-quarantined-files.txt 2012-06-29 01:42 ComboFix2.txt 2012-06-26 00:54 ComboFix3.txt 2012-06-24 19:18 ComboFix4.txt 2012-06-21 05:24 . Pre-Run: 604,504,481,792 bytes free Post-Run: 605,199,310,848 bytes free . - - End Of File - - 4F49021CC0EE5276A1A7F986BBD9DCA9
We need to see if we can find a clean copy of services.exe

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    *services.exe
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Here is the log SystemLook 30.07.11 by jpshortstuff Log created at 23:10 on 28/06/2012 by Owner Administrator - Elevation successful WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results. ========== filefind ========== Searching for "*services.exe" C:\Windows\erdnt\cache64\services.exe –a—- 384512 bytes [05:23 21/06/2012] [16:23 11/04/2009] 934E0B7D77FF78C18D9F8891221B6DE3 C:\Windows\System32\services.exe –a—- 279552 bytes [16:23 11/04/2009] [16:23 11/04/2009] D4E6D91C1349B7BFB3599A6ADA56851B C:\Windows\SysWOW64\services.exe –a—- 279552 bytes [16:23 11/04/2009] [16:23 11/04/2009] D4E6D91C1349B7BFB3599A6ADA56851B C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_2d69d4f782c83d8c\services.exe –a—- 384512 bytes [16:23 11/04/2009] [16:23 11/04/2009] 934E0B7D77FF78C18D9F8891221B6DE3 C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe –a—- 279552 bytes [16:23 11/04/2009] [16:23 11/04/2009] D4E6D91C1349B7BFB3599A6ADA56851B -= EOF =-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI